Turla is a long-running Russian state-linked espionage threat actor widely tracked under aliases including Secret Blizzard, Pensive Ursa, Waterbug, Snake, Uroburos, Venomous Bear, and Krypton. The group is associated with the Russian intelligence apparatus and is known for sustained cyber-espionage operations against governments, diplomatic missions, defense organizations, NGOs, and other strategically relevant entities, particularly in Ukraine and Eastern Europe. Turla is notable for maintaining a large and evolving malware ecosystem over many years. Tooling publicly associated with the group includes Kazuar, TinyTurla, ComRAT, Crutch, LightNeuron, Mosquito, Gazer, Snake/Uroburos, Carbon, HyperStack, CAPIBAR, Wipbot, FlyingYeti, and other loaders, wrappers, web shells, and specialized implants. The actor has demonstrated cross-platform development and operational flexibility, including Windows-focused backdoors, Outlook- and Exchange-oriented implants, Linux and macOS variants, and covert command-and-control approaches such as satellite-based communications. Operationally, Turla is characterized by stealthy, persistent intrusions and post-compromise tradecraft aligned with intelligence collection. Reported techniques include watering-hole operations, adversary-in-the-middle activity against diplomats, abuse of compromised third-party infrastructure, malware loading frameworks, long-term persistence mechanisms, and tailored espionage implants for email access and remote code execution. The group has also been reported using the tools or infrastructure of other threat actors to obscure attribution and expand victim access. Kazuar is one of the malware families most consistently associated with Turla. It has been described as a multiplatform espionage backdoor and has continued to evolve through newer loaders and wrappers. TinyTurla and related tooling have likewise been used in targeted spying operations, including campaigns against civil society organizations. Across reporting over more than a decade, Turla has remained one of the most prominent Russian cyber-espionage actors, distinguished by technical sophistication, operational longevity, and a focus on high-value intelligence targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.